Files
feedc0de 9ae5e84d97
Validate and deploy Kubernetes Dashboard / validate (push) Successful in 17s
Validate and deploy Kubernetes Dashboard / deploy (push) Successful in 24s
Fix CI/CD
2026-09-05 18:17:06 +02:00

69 lines
2.7 KiB
Bash
Executable File

#!/usr/bin/env bash
set -euo pipefail
project_dir=$(cd -- "$(dirname -- "${BASH_SOURCE[0]}")" && pwd)
workdir=$(mktemp --directory)
trap 'rm -rf "${workdir}"' EXIT
sh -n "${project_dir}/install.sh"
bash -n \
"${project_dir}/pin-images.sh" \
"${project_dir}/render.sh" \
"${project_dir}/create-ci-kubeconfig.sh" \
"${project_dir}/wait-for-deployments.sh" \
"${project_dir}/test.sh"
awk -f "${project_dir}/filter-secrets.awk" /dev/null >/dev/null
"${project_dir}/render.sh" "${workdir}/dashboard.yaml"
if grep -Eq '^kind:[[:space:]]*Secret[[:space:]]*$' "${workdir}/dashboard.yaml"; then
echo "Restricted CI render contains a Secret" >&2
exit 1
fi
if rg -i 'Bearer [A-Za-z0-9._-]{20,}|token:[[:space:]]*[A-Za-z0-9._-]{20,}' "${project_dir}" \
--glob '*.yaml' --glob '*.yml'; then
echo "A bearer token appears to be committed" >&2
exit 1
fi
grep -Fq 'kubernetes-dashboard-auth-proxy' "${project_dir}/kubernetes-dashboard-ingressroute.yaml"
grep -Fq 'name: kubernetes-dashboard-authentik' "${project_dir}/kubernetes-dashboard-ingressroute.yaml"
grep -Fq 'authentik-server.authentik.svc.cluster.local/outpost.goauthentik.io/auth/traefik' \
"${project_dir}/kubernetes-dashboard-ingressroute.yaml"
if grep -Fq 'namespace: default' "${project_dir}/kubernetes-dashboard-ingressroute.yaml"; then
echo "Dashboard route must not use a cross-namespace middleware" >&2
exit 1
fi
if grep -Fq 'rollout status' "${project_dir}/.gitea/workflows/deploy.yml"; then
echo "Restricted CI must poll exact Deployment names instead of list/watch" >&2
exit 1
fi
grep -Fq 'expirationSeconds: 3600' "${project_dir}/auth-proxy.yaml"
grep -Fq 'proxy_pass https://kubernetes-dashboard-kong-proxy' "${project_dir}/auth-proxy.yaml"
grep -Fq 'containerPort: 8443' "${workdir}/dashboard.yaml"
grep -Fq 'dashboard-api:1.14.0@sha256:2bd14c0ffee99d15fb1595644ebd1083ac32c5157c6e6fd8615b0f556a1390c2' "${workdir}/dashboard.yaml"
request_count=$(awk '
$1 == "cpu:" && $2 == "25m" { count++ }
END { print count + 0 }
' "${workdir}/dashboard.yaml")
if [[ "${request_count}" -lt 5 ]] || grep -Fq 'cpu: 100m' "${workdir}/dashboard.yaml"; then
echo "Expected every Dashboard chart component to request only 25m CPU" >&2
exit 1
fi
image=ghcr.io/yannh/kubeconform:v0.7.0@sha256:85dbef6b4b312b99133decc9c6fc9495e9fc5f92293d4ff3b7e1b30f5611823c
for file in \
"${workdir}/dashboard.yaml" \
"${project_dir}/kubernetes-dashboard-user.yaml" \
"${project_dir}/auth-proxy.yaml" \
"${project_dir}/kubernetes-dashboard-ingressroute.yaml" \
"${project_dir}/ci-deployer.yaml"
do
docker run --rm --interactive "${image}" \
-strict -exit-on-error -ignore-missing-schemas -summary < "${file}"
done
echo "Dashboard public desired state is valid and contains no static credentials."